English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16083
À§Çèµµ 30
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç WS FTP ¼­¹ö ¹öÀü¿¡ µû¸£¸é, WS FTP ¼­¹ö¿¡´Â CWD ¸í·É ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Ipswitch »ç¿¡¼­ °³¹ßÇÑ WS FTP´Â Microsoft Windows Ç÷§Æû »ó¿¡¼­ »ç¿ë °¡´ÉÇÑ FTP ¼­¹öÀÌ´Ù. WS_FTP Server ¹öÀü 1.0.1E ±×¸®°í 1.0.2E´Â ¸Å¿ì ±ä ¹®ÀÚµéÀÌ Àμö·Î µû¸£´Â 'CWD' ¸í·É¿¡ ´ëÇÑ ºÒÃæºÐÇÑ ±æÀÌ °Ë»ç·Î ÀÎÇÑ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ ÀÎÁõ¹ÞÀº °ø°ÝÀÚ´Â 876°³ ÀÌ»óÀÇ ¹®ÀÚµéÀ» °¡Áø CWD ¸í·ÉÀ» º¸³» FTP ¼­ºñ½º¸¦ Å©·¡½¬ ½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç WS FTP ¼­¹öÀÇ ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.osvdb.org/937

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Ipswitch, Inc., WS_FTP Server 1.0.1 EVAL
Ipswitch, Inc., WS_FTP Server 1.0.2 EVAL
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ Ipswitch WS_FTP ¼­¹ö ÆÐÄ¡ ¹× ¾÷±×·¹ÀÌµå »çÀÌÆ®·ÎºÎÅÍ WS_FTPÀÇ °¡Àå ÃֽйöÀü(5.02 ȤÀº ÀÌÈÄ)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.ipswitch.com/support/WS_FTP-Server/patch-upgrades.html
°ü·Ã URL CVE-1999-0362 (CVE)
°ü·Ã URL 217 (SecurityFocus)
°ü·Ã URL 1694 (ISS)